.text .globl _start _start: call p .asciz "/tmp/pwn" p: xorq %rdi, %rdi pop %rdi #shr $0x8, %rdi push $0xfffffffffffffd66 xor %rsi, %rsi pop %rsi neg %rsi push $85 pop %rax syscall xorq %rax, %rax xorq %rdi, %rdi push $42 pop %rdi push $61 pop %rax lea -1(%rax), %rax syscall